TalkFlow Privacy Policy

Last updated: June 24, 2026

This Privacy Policy describes how TalkFlow ("TalkFlow," "we," "us," or "our") collects, uses, discloses, stores, and protects information in connection with the TalkFlow platform and related websites, applications, and services (collectively, the "Services"), available at https://www.talkflow.us. TalkFlow is a multi-tenant Software-as-a-Service (SaaS) platform that provides AI-powered voice and chat agents for phone-based and chat-based customer service. The Services help our business customers answer calls and messages, qualify leads, schedule appointments, handle requests, and generate usage-based billing. This Privacy Policy is publicly accessible and is not located behind any login. If you do not agree with this Privacy Policy, please do not use the Services. This Privacy Policy may be published on the same public page as our Terms of Service / End User License Agreement ("Terms"), with each section linkable via anchor tags.

1. Introduction & Scope

TalkFlow is offered primarily to businesses in the United States. While the product interface may be available in additional languages (including Portuguese and Spanish), this Privacy Policy and our Terms are provided in English for our U.S. market.

This Privacy Policy applies to two distinct relationships:

  • Where we act as a controller (or "business" under U.S. law): for the personal information of our own account holders, including organization owners, staff sub-users, and platform administrators ("Account Data"). We determine the purposes and means of processing this information, and this Privacy Policy governs how we handle it.
  • Where we act as a processor (or "service provider"): for the personal information that our business customers (each an "organization" or "Client") collect from, or generate about, their own end-customers, callers, and patients through their use of the Services ("Client End-Customer Data"). For this category, the Client is the controller and is responsible for the lawfulness of collection and for the privacy notices given to its own end-customers. We process Client End-Customer Data only on the Client's behalf, in accordance with our agreement with that Client and this Privacy Policy.

A note on the QuickBooks Online (Intuit) integration. Our role with respect to data accessed through the QuickBooks Online integration is different from both of the relationships above and is described separately in Section 10. With respect to QuickBooks data, TalkFlow and Intuit each act as independent controllers.

When the GDPR / UK GDPR applies. Although TalkFlow focuses on the U.S. market, the EU and UK General Data Protection Regulation ("GDPR" / "UK GDPR") may nonetheless apply in certain circumstances — for example, where an account holder is located in the EEA or the UK, or where a Client uses the Services to handle calls and messages with end-customers who are located in the EEA or the UK. Where and to the extent the GDPR or UK GDPR applies, the GDPR-specific provisions of this Privacy Policy (including Sections 4, 6, 11, 12, 13, 14, and 16) apply. Where they do not apply, those provisions do not create obligations beyond what the law requires.

See Section 4 for a more detailed explanation of the controller/processor distinction.

2. Definitions / Key Terms

  • Personal Data / Personal Information: any information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular individual or household.
  • Processing: any operation performed on personal data, such as collection, recording, storage, use, disclosure, or deletion.
  • Controller / Business: the entity that determines the purposes and means of processing personal data.
  • Processor / Service Provider: an entity that processes personal data on behalf of, and under the instructions of, a controller.
  • Data Subject / Consumer: the individual to whom personal data relates.
  • Sensitive Data / Sensitive Personal Information: categories of data given special protection under applicable law (for example, health-related information, precise geolocation, or government identifiers).
  • Account Data: personal information about our own account holders, for which TalkFlow is the controller.
  • Client / Organization: a TalkFlow business customer that uses the Services to serve its own end-customers.
  • Client End-Customer Data: personal information about a Client's end-customers, callers, or patients that TalkFlow processes on the Client's behalf as a processor.
  • Subprocessor: a third party engaged by TalkFlow to process personal data in connection with the Services.
  • Services: the TalkFlow platform, websites, applications, and related offerings.

3. Information We Collect (Categories of Personal Data)

A. Information you provide directly (Account Data): - Account and identity information: name, email address, and a password (stored only as a salted hash through our authentication provider; we do not store plaintext passwords). - Role and membership information: your role (e.g., organization owner, staff sub-user, or platform administrator) and the organization(s) you belong to. - Organization / business information: business name, time zone, business hours, plan selection, and billing configuration. - Billing and invoicing information: billing details, plan and usage charges, invoice records, and payment-related metadata. Card payment details are handled by our payment processor and are not stored by TalkFlow on its own servers.

B. Information collected automatically: - Device and log data: IP address, browser type, device identifiers, access times, and similar technical information. - Usage data: product interactions and usage metrics such as call minutes and message counts, which are used for billing and service operation. - Cookies and session tokens: used for authentication and to keep you signed in (see Section 16).

C. Client End-Customer Data (processed on behalf of our Clients): When a Client uses the Services to handle calls and messages with its own end-customers, the Services may process, on that Client's behalf: - caller and end-customer names and phone numbers; - appointment details; - medication-check queries and other free-text requests submitted to the agent; - conversation metadata; - call recordings and call transcripts; and - chat transcripts.

Some of this content may include health-related information (for example, medication-check queries). Where it does, the relevant Client is responsible, as controller, for establishing a lawful basis and for any applicable privacy notices and consents. TalkFlow processes such data only on the Client's behalf and under the Client's instructions (see also Sections 4 and 18 regarding sensitive data, health data, and recording/SMS consent).

D. QuickBooks Online (Intuit) data (accessed via the integration). Where a connection to QuickBooks Online is authorized, TalkFlow accesses limited QuickBooks data (company information, customers, items, and invoices) solely to create and reconcile usage-based invoices. This is described in detail in Section 10.

Mapping to U.S. statutory categories (CCPA/CPRA). Depending on context, the information above may fall within the following statutory categories: identifiers; customer records / commercial information; internet or other electronic network activity information; audio/electronic information (call recordings); geolocation (e.g., information inferable from IP address); and, in some cases involving Client End-Customer Data, information that may be sensitive (e.g., health-related). We collect these categories for the business purposes described in Section 6. See Section 5 for the sources of these categories and Section 20 for the categories of recipients and retention periods.

4. Controller vs. Processor — Data We Control vs. Data We Process for Clients

Because TalkFlow is a B2B platform, it is important to distinguish the roles we play.

Data we control (Account Data). For information about our own account holders — owners, staff sub-users, and platform administrators — TalkFlow is the controller (or, under U.S. state law, the "business"). We decide why and how this data is processed, and the rights and choices described in Sections 13–14 apply to TalkFlow directly.

Data we process on behalf of Clients (Client End-Customer Data). For information about a Client's end-customers, callers, and patients, the Client is the controller and TalkFlow is a processor / service provider. We process this data only: - to provide and operate the Services for that Client; - in accordance with our agreement (including any Data Processing Addendum) with that Client; and - under the Client's documented instructions.

We do not use Client End-Customer Data for our own independent purposes, do not sell it, and do not use it for advertising. If you are an end-customer of one of our Clients and wish to exercise privacy rights over your data, please contact the relevant Client (the business you interacted with), which is the controller of that data; we will support that Client in responding to your request as required by law.

Call recording, SMS, and telephony consent. For call recording and SMS messaging delivered through the Services, the relevant Client, as controller, is solely responsible for obtaining any legally required consent — including call-recording consent in two-party-consent ("all-party-consent") jurisdictions such as California and Florida, and any consent required under the Telephone Consumer Protection Act (TCPA) and applicable SMS regulations. TalkFlow provides the recording and messaging functionality but does not determine the lawful basis for, or obtain consent for, the Client's communications with its end-customers.

Sensitive and health-related data. The Services are intended for general business customer-service use and are not designed to create a HIPAA covered-entity or business-associate relationship. TalkFlow does not act as a HIPAA Business Associate unless a separate Business Associate Agreement (BAA) has been executed in writing between TalkFlow and the relevant Client. Where Client End-Customer Data includes sensitive or health-related information, TalkFlow processes it only on the Client's instruction, solely to provide the Services, and does not use it to infer characteristics about any individual.

QuickBooks data — a distinct role. TalkFlow's role with respect to data accessed through the QuickBooks Online integration differs from both roles above. With respect to QuickBooks data, TalkFlow and Intuit act as independent controllers, as further explained in Section 10.

Multi-tenant isolation. Each organization's data is logically isolated from other organizations. We enforce tenant isolation at the database layer using managed database logical tenant isolation controls, so that one Client's data is not accessible to another Client through the Services.

5. Sources of Personal Information

We collect the categories of personal information described in Section 3 from the following sources:

  • Directly from account holders. Account and identity information, role and membership information, organization/business information, and billing configuration are provided directly by our account holders (owners, staff sub-users, and platform administrators) when they register for and use the Services.
  • Automatically from your use of the Services. Device and log data (e.g., IP address, browser type, device identifiers, access times), usage data (e.g., call minutes, message counts), and cookies/session tokens are collected automatically as you interact with the Services.
  • From our Clients (for Client End-Customer Data). Caller and end-customer names and phone numbers, appointment details, free-text and medication-check queries, conversation metadata, call recordings, call transcripts, and chat transcripts are generated through, and collected on behalf of, the relevant Client during interactions between that Client's agents and its own end-customers.
  • From third-party integrations. Where an integration is enabled and authorized, we receive data from connected third-party services, including: QuickBooks Online company information, customer records, items, and invoices (via the Intuit integration); and appointment/calendar data (via Google Calendar or Microsoft Outlook Calendar, where a Client enables it).

This section is provided in part to satisfy the source-disclosure requirements of the California Consumer Privacy Act, as amended by the CPRA, and similar U.S. state privacy laws.

6. How We Use Your Information (Purposes of Processing)

We use personal data for the following purposes: - Provide and operate the Services: deliver AI voice and chat agents, answer and route calls and messages, qualify leads, schedule appointments, and handle requests. - Account management: create and administer accounts, authenticate users, and manage organization membership and roles. - Billing and invoicing: measure usage (e.g., call minutes, message counts) and generate usage-based invoices, including creating and syncing invoices and payment links through our invoicing and payment partners. - Customer support: respond to inquiries and troubleshoot issues. - Security and fraud prevention: protect the Services, detect and prevent abuse, and maintain the integrity of our systems. - Service improvement and analytics: understand how the Services are used and improve reliability and functionality. - Communications: send service, transactional, and administrative messages. - Legal compliance: comply with applicable laws, respond to lawful requests, and enforce our agreements.

For Client End-Customer Data, we use the data only to provide the Services to the relevant Client and as instructed by that Client; we do not use it for our own purposes. For QuickBooks data accessed via the integration, we use it solely for the invoicing purpose described in Section 10.

7. Legal Bases for Processing (GDPR / UK GDPR)

Where and to the extent the GDPR or UK GDPR applies (see Section 1), we rely on the following legal bases for processing Account Data for which we are the controller: - Performance of a contract (Art. 6(1)(b)) — to provide the Services to our account holders and administer accounts and billing. - Legitimate interests (Art. 6(1)(f)) — to secure, operate, and improve the Services and to prevent fraud, balanced against your rights and freedoms. - Legal obligation (Art. 6(1)(c)) — to comply with applicable laws, including tax, accounting, and record-keeping requirements. - Consent (Art. 6(1)(a)) — where we rely on your consent (for example, for certain cookies or optional communications), which you may withdraw at any time.

Where TalkFlow acts as a processor for Client End-Customer Data, the relevant Client (as controller) is responsible for establishing the legal basis for processing, including any condition required under Art. 9 for special-category (e.g., health-related) data.

8. How We Share / Disclose Information

We disclose personal data only in the following circumstances: - Subprocessors / service providers: to the third parties listed in Section 9, who process data on our behalf to provide the Services, under written contracts that require appropriate data protection and security safeguards. - Within an organization: Account Data and the relevant Client's own data are accessible to authorized users of that same organization according to their roles. We do not disclose one Client's data to another Client. - Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Privacy Policy. - Legal and regulatory disclosures: where required to comply with applicable law, legal process, or a lawful governmental request, or to protect the rights, property, or safety of TalkFlow, our users, or others.

We do not disclose personal data to third parties for those third parties' own independent purposes, and we do not disclose QuickBooks/Intuit data except to the limited extent needed to provide the invoicing functionality you have authorized (see Section 10).

9. Third-Party Subprocessors / Service Providers

We engage the following subprocessors to provide the Services. Each is bound by a written agreement imposing data-protection and security obligations consistent with applicable law and with our obligations to our Clients and integration partners. We may update this list as our operations evolve; the current list is maintained here and material additions are communicated as described in Section 21.

SubprocessorPurposeProcessing Location / Notes
Cloud database & hostingmanaged database, authentication, and hosting / data storagePrimary data region: South America
Application hostingApplication hostingUnited States
AI voice & chat processingAI voice and chat agent processing; processes call/chat content and transcriptsUnited States. This provider may engage sub-subprocessors under back-to-back obligations, including a large language model provider used to generate agent responses
Telephony & SMSTelephony and SMS messaging (processes phone numbers and call/message routing)United States
Payment processingPayment processing (handles card payment data; PCI-DSS compliant)United States
Intuit / QuickBooks OnlineInvoicing and payment links (usage-based billing)United States — see Section 10
Google CalendarOptional appointment calendar synchronization (only if a Client enables it)United States
Microsoft (Outlook) CalendarOptional appointment calendar synchronization (only if a Client enables it)United States

We require each subprocessor, by written contract, to impose data-protection and security requirements at least as restrictive as those that apply to us under applicable law and under our integration-partner agreements, and we remain responsible for the acts and omissions of subprocessors that handle data on our behalf. Because certain subprocessors process data in the United States and one processes data in the South America region, personal data may be transferred internationally as described in Section 11.

10. QuickBooks Online (Intuit) Integration

This section describes how TalkFlow uses Intuit / QuickBooks Online data. It is provided to be prominent, accurate, and easy to understand.

Our role with respect to QuickBooks data (controller relationship). With respect to data accessed through the QuickBooks Online integration, TalkFlow and Intuit each act as independent controllers, consistent with Intuit's Developer Terms. The QuickBooks Online company data accessed through the integration belongs to the User / Client (the owner of the QuickBooks company). This is a role distinct from the processor role TalkFlow plays for call and chat Client End-Customer Data (see Section 4); accordingly, the controller/processor framing used elsewhere in this Privacy Policy and this independent-controller framing for QuickBooks data do not conflict.

Connection and authorization. TalkFlow integrates with a QuickBooks Online company using OAuth 2.0 provided by Intuit. The connection is established and authorized through Intuit's OAuth consent screen by the authorized administrator who manages the integration for the relevant organization, granting TalkFlow access to that organization's QuickBooks Online company. No QuickBooks data is accessed until the connection has been authorized.

What QuickBooks data we access. Through the authorized connection, TalkFlow accesses the following QuickBooks Online data: - Company information (the QuickBooks company profile / realm details); - Customers (customer records used to address invoices); - Items (products/services used as invoice line items); and - Invoices (to create and reconcile invoices).

Why we access it (purpose limitation). We access this data solely to create and sync usage-based invoices and payment links for the monthly TalkFlow bill. We use QuickBooks data only for this functional purpose of the Services and within the scope of the authorization granted.

What we do NOT do with Intuit data. - We do not sell QuickBooks/Intuit data, and we do not make it available to any third party for that third party's own use. - We do not use QuickBooks/Intuit data for advertising, marketing, profiling, benchmarking, or competitive-intelligence purposes. - We do not scrape, data-mine, harvest, index, or aggregate-and-distribute QuickBooks/Intuit data on a wholesale basis; we use it only for the functional invoicing purpose described above. - We never combine, surface, or use one customer's QuickBooks data across, or for the benefit of, any other customer. One customer's QuickBooks data is not shared with, or displayed to, any other customer. - We do not export, save, or store QuickBooks data for any purpose other than the functional invoicing use of the Services, and we do not provide third parties with access to QuickBooks data via external API calls or any other means, except the limited use by the subprocessors needed to render the Services.

We do not process Intuit data on Intuit's behalf. For clarity, TalkFlow does not process User Data or Personal Information on Intuit's behalf. As stated above, with respect to QuickBooks data, TalkFlow and Intuit act as independent controllers, each responsible for its own compliance with applicable law.

Consent and evidence of consent. TalkFlow obtains and maintains the User's consent for the access to and use of QuickBooks data described in this section, and can present evidence of that consent to Intuit on request. By authorizing the QuickBooks connection, the User consents to TalkFlow's access to and use of the data described above for the stated purpose.

OAuth token storage and security. OAuth access tokens and refresh tokens, together with the QuickBooks company identifier (realmId), are stored encrypted at rest using AES and transmitted only over encrypted (TLS) connections. The encryption key is managed separately from the encrypted token store. Access tokens are refreshed automatically using the refresh token only when needed. We do not expose Intuit OAuth tokens or customer-identifying information within the Services or to other parties, and we do not log QuickBooks data or credentials.

How you disconnect, and what happens to your data. You can disconnect QuickBooks Online from within TalkFlow at any time. On disconnect, TalkFlow calls Intuit's token-revocation endpoint to revoke the connection, immediately ceases accessing your QuickBooks data, and deletes the stored OAuth tokens associated with that connection. After disconnection, the Services can no longer make QuickBooks data calls for your company, and the option to reconnect ("Connect to QuickBooks") becomes available again. Signing out of TalkFlow does not, by itself, disconnect your QuickBooks company. If you revoke consent, terminate, or stop using the integration, we will immediately stop processing the related QuickBooks data and securely delete it, except where retention is required by law (for example, retaining invoice records for tax and accounting purposes).

11. International Data Transfers

TalkFlow is operated for a primarily U.S. audience, and our subprocessors may process data in the United States and in other regions, including, for our primary database, the South America region (see the location column in Section 9). As a result, personal data may be transferred to, stored in, and processed in countries other than the country in which it was collected, including countries that may have different data-protection laws.

Where and to the extent we transfer personal data subject to the GDPR or UK GDPR out of the EEA or the UK, we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), an adequacy decision, or another lawful safeguard. You may contact us using the details in Section 22 for more information about the safeguards we use.

12. Data Retention

We retain personal data for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Category-specific retention details, including for CCPA/CPRA purposes, are set out in the table in Section 20.

  • Account Data is retained for the duration of the account relationship and for a reasonable period thereafter, subject to legal, tax, and accounting requirements.
  • Client End-Customer Data (including call recordings, transcripts, and conversation metadata) is retained for the period configured in our agreement with, or under the instructions of, the relevant Client, and is deleted or returned on termination of that relationship, except where retention is required by law.
  • Billing and invoicing records, including data created through the QuickBooks integration, may be retained as required by applicable tax, accounting, and record-keeping laws (generally up to the period required by such laws).
  • QuickBooks OAuth tokens are deleted upon disconnection of the integration, as described in Section 10.

When personal data is no longer needed, we securely delete or anonymize it so that it is permanently sanitized and not recoverable, except for copies we are legally required to retain.

13. Your Privacy Rights

Depending on where you live and the role we play with respect to your data, you may have some or all of the following rights:

Under the GDPR / UK GDPR (where applicable): the rights to access, rectify, erase ("right to be forgotten"), restrict processing, data portability, and object to processing; the right to withdraw consent at any time (without affecting prior processing); and rights relating to automated decision-making and profiling (see Section 16).

Under the CCPA/CPRA and similar U.S. state laws: the rights to know/access the personal information we have collected, to delete it, to correct inaccurate information, to opt out of the sale or sharing of personal information (note: we do not sell or share — see Section 17), to limit the use and disclosure of sensitive personal information, and to non-discrimination for exercising your rights.

For Client End-Customer Data, where TalkFlow acts as a processor, please direct your request to the relevant Client (the business you interacted with), which is the controller. We will assist that Client in fulfilling your request as required by applicable law.

14. How to Exercise Your Rights / Submitting Requests

To exercise the rights described in Section 13 with respect to data for which TalkFlow is the controller, contact us at our official privacy channel: privacy@talkflow.us (see Section 22). We will: - Verify your identity before fulfilling your request, to protect your information from unauthorized access. We may ask for information sufficient to reasonably confirm your identity. - Honor authorized agents who submit requests on your behalf, subject to verification. - Respond within the timeframes required by applicable law.

If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority. If you are a California resident, you may contact the California Privacy Protection Agency or the California Attorney General. We encourage you to contact us first so we can address your concern.

15. Data Security

We implement technical and organizational measures designed to protect personal data, including: - Encryption in transit using TLS, and encryption at rest for stored data. - AES-encrypted storage of OAuth tokens, including QuickBooks Online access and refresh tokens, with the encryption key managed separately from the encrypted token store. - Multi-tenant isolation enforced at the database layer through managed database logical tenant isolation controls, so each organization's data is logically separated. - Access controls limiting access to personal data to authorized personnel and systems on a need-to-know basis. - Practices designed to avoid logging credentials or sensitive integration data.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We maintain policies and procedures to detect, prevent, respond to, and remediate security incidents.

Breach notification. In the event of a personal data breach or security incident, we will notify affected individuals, our Clients, and/or regulators as and when required by applicable law and by our contractual obligations. With respect to integration partners, we will notify Intuit of any security incident affecting Intuit data without undue delay and, in any event, no later than twenty-four (24) hours after discovery, in accordance with Intuit's Developer Terms.

Relationship to the Terms. The security commitments in this section are provided as described and are subject to the warranty disclaimers and limitation-of-liability provisions in our Terms. This Privacy Policy does not create, and should not be read to create, any liability cap, warranty, or remedy independent of the Terms; the limitation-of-liability and disclaimer sections of the Terms govern.

16. Cookies & Tracking Technologies; Automated Decision-Making

Cookies and similar technologies. We use cookies and session tokens that are necessary to authenticate users and keep you signed in. These are essential for the Services to function. Where required by law, we obtain consent for any non-essential cookies and provide a means to manage your preferences. You can also control cookies through your browser settings, although disabling essential cookies may prevent you from using the Services.

Automated decision-making and profiling. The Services use AI to handle and respond to calls and messages, qualify leads, and schedule appointments on behalf of our Clients. These automated interactions operate under the configuration and control of the relevant Client and are not used by TalkFlow to make decisions that produce legal or similarly significant effects about you without human involvement. Where the GDPR applies and any automated decision-making would produce legal or similarly significant effects, the associated rights under Article 22 apply, and you may contact us or the relevant Client to request human review.

17. Sale / Sharing of Personal Information & Targeted Advertising

We do not sell personal information, and we do not "share" personal information for cross-context behavioral (targeted) advertising, as those terms are defined under the California Consumer Privacy Act, as amended by the CPRA, and similar U.S. state privacy laws.

We do not use personal data — including any data obtained through the QuickBooks Online integration — for advertising or marketing to third parties. We honor opt-out preference signals, including the Global Privacy Control (GPC), where required by applicable law. Because we do not sell or share personal information, there is no "Do Not Sell or Share My Personal Information" sale to opt out of; however, you may still exercise the rights described in Sections 13–14.

Aggregated and anonymized data (non-Intuit data only). If TalkFlow derives operational or product insights from data across multiple Client accounts, it will do so only on an aggregated and anonymized basis that does not identify any individual, Client, or end-customer. This aggregation practice applies only to non-Intuit data and never to QuickBooks/Intuit data: as stated in Section 10, one customer's QuickBooks data is never combined, surfaced, or used across, or for the benefit of, any other customer.

18. Children's Privacy

The Services are intended for businesses and are not directed to children, and TalkFlow does not target or market the Services to any consumer age group. With respect to data for which TalkFlow is the controller, we do not knowingly collect personal data from individuals under the minimum age applicable in the relevant jurisdiction (for example, under 13 under the U.S. Children's Online Privacy Protection Act, or under 16 where a higher threshold applies under certain GDPR member-state laws). If you believe a child has provided us personal data for which we are the controller, please contact us using the details in Section 22 and we will take appropriate steps to delete it.

Where a Client's end-customer data may relate to minors, the relevant Client, as controller, is responsible for obtaining any required parental consent and for compliance with applicable children's privacy laws.

19. Third-Party Links & Services

The Services may integrate with or link to third-party products and services, including the subprocessors listed in Section 9 (for example, Intuit/QuickBooks Online, Google Calendar, and Microsoft (Outlook) Calendar). These third parties have their own privacy policies and practices, and this Privacy Policy does not govern their handling of your data once it is processed under their own terms. We encourage you to review the privacy policies of any third-party services you connect or use.

20. Region-Specific Disclosures

EEA / UK (GDPR / UK GDPR). Where and to the extent the GDPR or UK GDPR applies (see Section 1), Sections 4, 7, 11, 12, 13, 14, and 16 contain disclosures specific to data subjects in the EEA and the UK, including legal bases, international transfer mechanisms, and your statutory rights. Where required, our EU/UK representative and/or Data Protection Officer details are provided in Section 22.

California (CCPA / CPRA). The categories of personal information we collect and the purposes for which we use them are described in Sections 3 and 6; the sources of personal information are described in Section 5; and the categories of recipients and the retention periods for each category are set out in the table below. As stated in Section 17, we do not sell or share personal information and do not use it for cross-context behavioral advertising. California residents also have rights under California's "Shine the Light" law; because we do not disclose personal information to third parties for their own direct marketing, no such disclosures are made. We do not offer financial incentives in exchange for personal information.

Category of personal information collectedCategories of recipients it is disclosed toRetention period / criteria
Identifiers (name, email, IP address, device identifiers, role/organization membership)Hosting and database providers; for Client End-Customer identifiers, the AI agent and telephony providers; invoicing/payment providers (including QuickBooks Online) as applicableAccount-related identifiers: for the duration of the account relationship plus a reasonable period thereafter, subject to legal/tax requirements. Client End-Customer identifiers: per the Client's instructions/agreement, deleted or returned on termination
Customer records / commercial information (business name, plan, billing config, usage charges, invoice records)Hosting/database providers; invoicing/payment providers (including QuickBooks Online)As required by applicable tax, accounting, and record-keeping laws
Internet / electronic network activity information (usage data, log data, product interactions)Hosting/database and application providersRetained for service operation, security, and billing for the period reasonably necessary for those purposes
Audio / electronic information (call recordings, transcripts, chat transcripts)AI agent and telephony providers; our database/storage providerPer the relevant Client's instructions/agreement; deleted or returned on termination of the Client relationship, except where retention is required by law
Geolocation (coarse location inferable from IP address)Hosting/database and application providersRetained as part of log data for the period reasonably necessary for security and operations
Sensitive personal information (e.g., health-related content within Client End-Customer Data, such as medication-check queries)AI agent and telephony providers; our database/storage provider — processed only on Client instructionPer the relevant Client's instructions/agreement; deleted or returned on termination of the Client relationship, except where retention is required by law. Not used to infer characteristics

Other U.S. states and jurisdictions. Residents of other U.S. states with comprehensive privacy laws, and individuals protected under laws such as Brazil's LGPD and Canada's PIPEDA, may have rights similar to those described in Section 13. Contact us to exercise applicable rights.

21. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Services. When we make changes, we will revise the "Last Updated" date associated with this policy. For material changes, we will provide additional notice as required by applicable law (for example, by email or by an in-product notice). We will also promptly notify our integration partners, including Intuit, of changes that affect how we collect, store, handle, or process data, and of any updates to the disclosures, terms, and privacy policies we provide to users, as required under our agreements with them. Your continued use of the Services after an update becomes effective constitutes your acceptance of the updated Privacy Policy.

22. Governing Law & Venue

This Privacy Policy is governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-laws principles. The parties submit to the exclusive jurisdiction of the state and federal courts located in the State of Delaware, United States for any dispute arising out of or relating to this Privacy Policy, except where mandatory data-protection laws of your jurisdiction grant you rights or remedies in your local courts, which are not waived by this section. Where this Privacy Policy is published alongside our Terms, any governing-law and dispute-resolution provisions in the Terms also apply to the extent relevant.

23. Contact Us / Data Protection

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

  • Legal entity: TalkFlow
  • Mailing address: admin@talkflow.us
  • Privacy / rights-request channel (official): privacy@talkflow.us
  • General contact (fallback): admin@talkflow.us
  • Website: https://www.talkflow.us

For data-subject and consumer rights requests (Sections 13–14), please use the official channel, privacy@talkflow.us, so your request is routed and tracked within the response deadlines required by law.

Data Protection Officer / EU-UK Representative. Where required under GDPR Article 27 or otherwise applicable, our Data Protection Officer and/or EU-UK representative may be contacted via privacy@talkflow.us.